Originally Posted by gr8scot
but it should be
$IPTABLES -A PREROUTING -t nat -i $EXTIF -p tcp --dport 8080 -j DNAT --to-destination 192.168.3.2:3128
No, this rule should not be applied to the external interface, it should not be applied to packets destined to port 8080, and it should not DNAT to port 3128. It is meant to be applied to HTTP packets (TCP port 80) coming into the internal interface, sending them to DansGuardian (which listens on port 8080). Either way, it doesn't really matter, as you shouldn't be resurrecting dead threads unless it's absolutely necessary. Please let this thread rest in peace.